YSK Limited ("YSK", "we", "us", or "our") is a Hong Kong–based technology company providing remote developer outsourcing, custom software development, cloud hosting, enterprise AI deployment, proprietary SaaS products, and the public website blog at ysk.hk/blog. This Privacy Policy and Service Terms ("Policy") explains how we collect, use, disclose, and protect personal data, and sets out important terms governing our relationship with you when you use our website (including the Blog), engage our professional services, or access our products.
By accessing ysk.hk (including /blog, short links under /r/, search and tag pages), contacting us, signing a service agreement, uploading materials to our systems, or using any YSK-managed application, you acknowledge that you have read and understood this Policy. Where a separate written contract, statement of work, or product licence exists, that document prevails in the event of conflict, except that this Policy applies to baseline privacy and data-handling obligations unless expressly superseded.
This Policy applies to: (a) visitors to our website, Blog, and marketing channels; (b) Clients and their authorised personnel; (c) End Users of YSK Products; and (d) End Users of applications developed, hosted, or maintained by YSK on a Client's behalf, where YSK processes data as instructed by that Client.
YSK acts as a data user (controller) for data collected through our website (including the Blog), billing, account administration, and YSK Products. For Client Materials and End User data processed solely to deliver bespoke development or managed hosting, YSK typically acts as a data processor / service provider on the Client's instructions. Clients remain responsible for establishing a lawful basis and providing appropriate notices to their own End Users.
Depending on your relationship with YSK, we may collect the following categories of data:
We do not intentionally collect sensitive personal data (e.g. health, biometric, or financial account credentials beyond billing) unless required for a specific engagement and agreed in writing. Clients must not submit special-category data to general-purpose systems without prior written approval and appropriate safeguards. The public Blog does not require reader registration and does not provide public commenting.
We use Personal Data only where permitted under the PDPO and applicable law, including for:
We do not sell Personal Data. We do not use Client Materials or confidential datasets to train public or general-purpose AI models unless you provide explicit written consent for a defined purpose.
Clients are responsible for the accuracy, legality, and authority of all Client Materials and instructions provided to YSK. Clients must ensure that collection and transfer of End User data to YSK complies with applicable privacy laws and that required consents and privacy notices are in place.
Prohibited uses include uploading malware, unlawful content, data obtained without authority, or materials that would cause YSK to breach law or platform policies (including Apple App Store and Google Play requirements). We may suspend access where we reasonably believe a breach has occurred.
Certain Services involve AI-assisted development, private large language model ("LLM") deployment, inference APIs, chatbots, or automation workflows. You acknowledge that AI systems are probabilistic and may produce incomplete, outdated, or incorrect outputs ("hallucinations").
We implement appropriate technical and organisational measures consistent with PDPO Data Protection Principle 4, including encryption in transit and at rest where appropriate, access controls, logging, patching, and least-privilege administration. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
Hosting locations depend on the Service: standard plans may include dedicated virtual servers in approved jurisdictions (e.g. United States) as described in your plan; private LLM and on-premises deployments follow the architecture agreed in writing. Cross-border transfers, where applicable, are limited to what is necessary for service delivery and protected by contractual safeguards. Unauthorized transfers of Client Materials outside agreed environments are prohibited.
We may disclose Personal Data to:
Our Services may integrate third-party platforms (e.g. cloud providers, app stores, messaging APIs, blockchain networks). YSK is not responsible for the privacy practices of third parties outside our control. Clients are responsible for reviewing third-party terms applicable to their projects.
We retain Personal Data only for as long as necessary for the purposes described above, including:
Deletion requests may be sent to [email protected]. We will action verified requests within 14 business days for active systems, subject to legal retention obligations and backup cycles. Where YSK processes data on behalf of a Client, End Users should contact the Client first; YSK will assist the Client as reasonably required.
Subject to the PDPO and applicable exceptions, you may request access to or correction of Personal Data held about you. Requests should be sent to [email protected] with sufficient identity verification. We aim to respond within 40 days. A reasonable fee may be charged for manifestly unfounded or excessive access requests. You may lodge a complaint with the Office of the Privacy Commissioner for Personal Data (PCPD), Hong Kong.
Our website (including the Blog) may use essential cookies for security and basic functionality (for example, maintaining an authenticated session on restricted administration pages). Where analytics or preference cookies are used, we will provide appropriate notice. You may control cookies through your browser settings; disabling certain cookies may affect site functionality.
The Blog publishes publicly available articles, images, tags, and related materials on topics such as technology, AI, Web3, and industry news, together with YSK marketing information. Content may summarise or comment on publicly reported information; titles, commentary, and presentation are produced for YSK's website and marketing purposes.
Except as expressly stated in a signed agreement, Services and Products are provided on an "as is" and "as available" basis. To the fullest extent permitted by Hong Kong law, YSK disclaims all implied warranties, including merchantability, fitness for a particular purpose, and non-infringement.
YSK is not liable for delay or failure caused by events beyond reasonable control, including upstream cloud or app-store outages, network failures, cyberattacks, natural disasters, labour disputes, or government actions. We may update this Policy from time to time; material changes will be posted at ysk.hk/privacy-policy with an updated effective date. Continued use after changes constitutes acceptance where permitted by law.
Each party shall protect the other's confidential information using reasonable care and use it only for the engagement. Unless otherwise agreed in writing, Clients retain ownership of Client Materials and pre-existing IP; YSK retains ownership of its pre-existing tools, frameworks, and general know-how. Deliverable ownership is governed by the applicable service contract.
This Policy is governed by the laws of the Hong Kong Special Administrative Region. Disputes shall first be addressed through good-faith negotiation. If unresolved, parties may refer the matter to mediation or arbitration at the Hong Kong International Arbitration Centre (HKIAC) under its applicable rules. If any provision is held invalid, the remainder remains in effect.
YSK Limited — Legal & Privacy
Privacy enquiries: [email protected] | General: [email protected] | WhatsApp: +852 6160 4242
YSK Limited(「YSK」、「本公司」或「我們」)為總部位於香港的科技公司,提供開發者外判、客製化軟件開發、雲端託管、企業 AI 部署、自有 SaaS 產品,以及位於 ysk.hk/blog 的公開網站網誌。本《私隱政策及服務條款》(「本政策」)說明我們如何收集、使用、披露及保護個人資料,並列明您使用本公司網站(包括網誌)、委託專業服務或使用本公司產品時的重要法律條款。
當您瀏覽 ysk.hk(包括 /blog、/r/ 短網址、搜尋及標籤頁面)、聯絡我們、簽署服務合約、向本公司系統上傳資料,或使用任何由 YSK 管理之應用程式,即表示您已閱讀並理解本政策。如另有書面合約、工作說明書或產品授權協議,該文件與本政策有衝突時以該文件為準;惟在未有明確取代的情況下,本政策適用於基本私隱及數據處理義務。
本政策適用於:(a) 本公司網站、網誌及營銷渠道之訪客;(b) 客戶及其授權人員;(c) YSK 產品之終端用戶;及 (d) 由 YSK 代客戶開發、託管或維護之應用程式之終端用戶(該情況下 YSK 按客戶指示處理資料)。
就本公司網站(包括網誌)、帳單、帳戶管理及 YSK 產品所收集之資料,YSK 為資料使用者(控制者)。就客戶材料及為提供客製化開發或託管服務而處理之終端用戶資料,YSK 通常為資料處理者/服務提供者,按客戶指示行事。客戶須自行確保處理其終端用戶資料之合法依據,並提供適當私隱通知。
視乎您與 YSK 的關係,我們可能收集以下類別的資料:
我們不會故意收集敏感個人資料(如健康、生物識別或超出帳單所需之金融帳戶憑證),除非特定項目需要且經書面同意及適當保障。客戶不得在未有事先書面批准下,向一般用途系統提交特殊類別資料。公開網誌無需讀者註冊,亦不提供公開留言功能。
我們僅在 PDPO 及適用法律允許下使用個人資料,包括:
我們不會出售個人資料。除非您就特定用途提供明確書面同意,我們不會使用客戶材料或機密數據集訓練公共或通用 AI 模型。
客戶須對所提供之客戶材料及指示的準確性、合法性及授權負責。客戶須確保向 YSK 提供終端用戶資料符合適用私隱法律,並已取得所需同意及私隱通知。
禁止用途包括上傳惡意程式、違法內容、未經授權取得之資料,或會令 YSK 違反法律或平台政策(包括 Apple App Store 及 Google Play 規定)之材料。如本公司合理相信發生違規,可暫停存取。
部分服務涉及 AI 輔助開發、私有大型語言模型(「LLM」)部署、推論 API、聊天機械人或自動化流程。您確認 AI 系統具概率性,可能產生不完整、過時或錯誤的輸出(「幻覺」)。
我們採取符合 PDPO 資料保護原則 4 之適當技術及組織措施,包括適當之傳輸中及靜態加密、存取控制、日誌記錄、修補程式及最小權限管理。任何傳輸或儲存方式均無法保證絕對安全。
託管地點視服務而定:標準計劃可能包括計劃說明之核准司法管轄區(例如美國)之獨立虛擬伺服器;私有 LLM 及本地部署則按書面協議之架構進行。跨境轉移(如適用)僅限於提供服務所需,並受合約保障約束。未經同意不得將客戶材料轉移至約定環境以外。
我們可能向以下各方披露個人資料:
服務可能整合第三方平台(如雲端供應商、應用商店、訊息 API、區塊鏈網絡)。YSK 對其控制範圍以外之第三方私隱做法不負責。客戶須自行審閱其項目適用之第三方條款。
我們僅在達成本政策所述目的所需期間內保留個人資料,包括:
刪除請求請電郵至 [email protected]。我們將於 14 個工作天內處理已核實之活躍系統請求,並受法律保留義務及備份週期約束。如 YSK 代客戶處理資料,終端用戶應先聯絡客戶;YSK 將在合理範圍內協助客戶履行義務。
在 PDPO 及適用例外規定下,您可要求查閱或更正本公司持有之您的個人資料。請電郵至 [email protected] 並提供足夠身份核實資料。我們目標於 40 日內回覆。對明顯無理或過度查閱請求,可收取合理費用。您亦可向香港個人資料私隱專員公署(PCPD)提出投訴。
本公司網站(包括網誌)可能使用必要 Cookie 以維持保安及基本功能(例如在受限制的管理頁面維持已驗證工作階段)。如使用分析或偏好 Cookie,我們將提供適當通知。您可透過瀏覽器設定管理 Cookie;停用部分 Cookie 可能影響網站功能。
網誌公開發佈文章、圖片、標籤及相關材料,涵蓋科技、AI、Web3 及行業新聞等主題,並附 YSK 營銷資訊。內容可能對公開報道資料作摘要或評論;標題、論述及編排乃為本公司網站及營銷目的而製作。
除簽署協議明確載明外,服務及產品按「現況」及「現有可用性」提供。在香港法律允許之最大範圍內,YSK 排除所有默示保證,包括適銷性、特定用途適用性及不侵權。
因合理控制範圍以外之事件(包括上游雲端或應用商店中斷、網絡故障、網絡攻擊、天災、勞資糾紛或政府行動)導致之延誤或未能履行,YSK 不承擔責任。我們可不時更新本政策;重大修訂將於 ysk.hk/privacy-policy 公布並更新生效日期。在法律允許下,修訂後繼續使用即構成接受。
各方須以合理謹慎保護對方保密資料,並僅用於相關項目。除書面另有約定,客戶保留客戶材料及既有知識產權;YSK 保留其既有工具、框架及一般專有技術。交付成果之權屬以適用之服務合約為準。
本政策受香港特別行政區法律管轄。爭議應先以善意協商解決;未能解決時,可提交香港國際仲裁中心(HKIAC)按其適用規則進行調解或仲裁。如任何條款被判定無效,其餘條款仍然有效。
YSK Limited — 法務及私隱
私隱查詢:[email protected] | 一般查詢:[email protected] | WhatsApp:+852 6160 4242